| To: | nn@qorbit.net |
|---|---|
| Subject: | [nn] Site-to-site VPN and WMI query failures |
| From: | Netfortius <netfortius@gmail.com> |
| Date: | Fri, 16 Mar 2007 08:15:32 -0500 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | ns-list2@consult.net |
| Delivered-to: | nn@qorbit.net |
| Dkim-signature: | a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:from:reply-to:to:subject:date:user-agent:mime-version:content-type:message-id; b=jWWJGn0ktEo0WlbQzLZnt+81rdGlGErHXQsh5RFvdM27dF18rQTmyus3BDFy2btWi4nXgcARED2E04DnIbe5ncBQT7dZ7L9SynsNzFGY030jZQTMxT08wb6eH5VnK/wqnzI8wiGPzRaa+kUHo+CtxhkosEnjJKRG1y9sqbu8ZFQ= |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:reply-to:to:subject:date:user-agent:mime-version:content-type:message-id; b=gQRTkZ3LVmtQPuw6nXOuYy7breYpW1PPs5cOoMJOyyW9FQ+n0Twfuec8KJh0GTAkKOXKsLGRyQAIZSE0EabciiSCoiH4fdge/LDNI8BFJ+kxbAF+6liWFhjosOb02tsQpPBCnMpWhCxjaOSMra4/KzHsDbpfL4nx97KvhiWrymk= |
| List-archive: | <http://www.qorbit.net/nn> |
| List-help: | <mailto:nn-request@qorbit.net?subject=help> |
| List-id: | "Netscreen mailing list for netscreen admins." <nn.qorbit.net> |
| List-post: | <mailto:nn@qorbit.net> |
| List-subscribe: | <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe> |
| List-unsubscribe: | <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe> |
| Reply-to: | netfortius@gmail.com |
| Sender: | nn-bounces@qorbit.net |
| User-agent: | KMail/1.9.5 |
I have a configuration with two sites (in fact many pairs like this, but the issue is the same for all pairs) with 5GTs, running all 5.3.0r4.0, connected via site-to-site VPN. There are no restrictions of traffic between the LANs behind the internal interface of each firewall, and no content rules (took them all out). On each LAN there is a Win2K3 DC, and all of those DCs communicate and sync just fine (i.e. normal Active Directory traffic works perfectly) When trying to use WMI mmc - i.e. query for WMI properties from one DC to another (which consists of some sort of RPC mapper process, first, followed by a DCE end points comm attempts, from a source dynamically assigned TCP port (the querier) to the destination (the queried system) - always on TCP135) this alwasy fails. What I can see from a trace being taken on the two DCs is that a specific segment sent by the querying machine never makes it through the tunnel to the other DC (getting dropped by the firewall). Does anybody see anything odd in such (failed/being dropped packet here attached - hoe this mailing list accepts attachments), that would lead to the above described failure? NOTE!! TCP checksum incorrect, as reported in the capture, is a tshark interpretation. Same "error" showing up in other traces does not keep other segments crossing the tunnel, and same "error" does not keep other DCs, on a LAN, to work just fine for the WMI queries. It is just the site-to-site VPN-oposed-DCs that fail. TIA, Stefan
_______________________________________________ nn mailing list nn@qorbit.net http://qorbit.net/mailman/listinfo/nn |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [nn] Mailing list manager, Stephen Gill |
|---|---|
| Next by Date: | [nn] Command rejected due to writing config conflict, Arno MESGUICH |
| Previous by Thread: | [nn] Mailing list manager, Stephen Gill |
| Next by Thread: | [nn] Command rejected due to writing config conflict, Arno MESGUICH |
| Indexes: | [Date] [Thread] [Top] [All Lists] |